Categories
Blog

The NBA/Clippers Investigation: Part 2 – Conflicts in the Commercial Ecosystem

The Clippers investigation demonstrates why conflict controls must follow influence, economic benefit, and interconnected transactions, not merely financial ownership. In Part 2 of this five-part series, we consider what conflicts of interest are, why they are so divisive, and why compliance professionals must stay vigilant to prevent them from arising.

The most consequential conflicts of interest rarely arrive with a label. They appear as introductions, relationship management, commercial creativity, customer accommodation, or an effort to satisfy an important stakeholder. Each step may look defensible on its own. The compliance risk becomes visible only when the organization connects the people, payments, contracts, incentives, and timing. That is one of the central lessons from the investigation into the LA Clippers and Kawhi Leonard salary cap circumvention.

The independent investigators’ report (Wachtell Report) concluded that the Clippers initiated and facilitated endorsement opportunities between Leonard and four companies doing business with the team: Aspiration Partners, Boingo Wireless, Daktronics, and Lockton Insurance. Investigators further found that the team induced those companies to enter the endorsement arrangements by offering or providing Clippers business.

This was not a traditional conflict involving an executive awarding a contract to a company the executive secretly owned. It was a commercial ecosystem in which organizational business, personal relationships, vendor incentives, and benefits for a powerful player allegedly became intertwined. The Athletic seemed to believe that these conflicts were all at the behest of Leonard’s personal representative, Uncle Dennis. But even if the requests originated from the Leonard Camp, the Clippers put the entire sordid process into motion.

The Conflict Was in the Network

Conflict programs often focus on a narrow question: Does the employee have a financial interest in the counterparty? That question matters, but it is not enough.

The Wachtell Report identified personal and professional relationships involving Clippers President of Business Operations Gillian Zucker and two of the companies. At one company, her husband served as board chair during the relevant period, and Zucker reportedly had a 30-year working relationship with its chief executive. At another, she had a longstanding relationship with the president and recommended him internally as the Clippers considered service providers.

Relationships do not establish wrongdoing. Longstanding connections can create legitimate business opportunities. The compliance issue is whether the relationships were disclosed, independently evaluated, and removed from decisions that could benefit the related parties or another favored stakeholder.

Aspiration presented a different form of entanglement. In September 2021, Aspiration entered into a 23-year, $382.5 million sponsorship arrangement with the Clippers, a 23-year, $72 million sustainability services agreement for the Intuit Dome, and an agreement under which Steve Ballmer personally invested $50 million in Aspiration. Weeks later, the process leading to Aspiration’s proposed endorsement agreement with Leonard began.

Again, an investment, sponsorship, services agreement, or endorsement relationship is not inherently improper. The risk arose from their combination. Investigators concluded that Clippers personnel participated in developing Leonard’s endorsement arrangement and later approved Forum business that Aspiration’s co-founder had linked to completion of that endorsement deal.

The compliance question was therefore not simply whether Ballmer had disclosed his investment. It was whether anyone independently assessed the total relationship and asked whether the organization, its owner, its vendor, and its player were participating in genuinely separate transactions.

Procurement Leverage as a Compliance Risk

The Wachtell Report’s discussion of Daktronics makes the commercial leverage particularly clear. Daktronics was competing for the Intuit Dome scoreboard and signage business. According to investigators, Clippers personnel proposed directing part of the vendor’s expected “spend back” to an endorsement agreement with Leonard.

Daktronics reportedly believed that refusing could jeopardize its opportunity to win the arena contract. Investigators found that a Clippers executive specified the proposed endorsement economics and later requested an additional payment after the scope of the scoreboard purchase increased.

This is a critical third-party risk lesson. A vendor may appear to make an independent payment, but the customer’s purchasing power can shape its decision. The organization cannot treat the vendor as an independent actor if its executives use procurement leverage to influence the vendor’s decision.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to examine the business rationale for using a third party, whether contracts accurately describe the services, whether the work was actually performed, whether compensation was commensurate with that work, and how third-party management is integrated into procurement and vendor management. Those questions apply well beyond anti-bribery enforcement.

They can be adapted to any commercial arrangement:

  • Why is this party entering the transaction?
  • Who proposed the arrangement and its economic terms?
  • Is another pending contract influencing the decision?
  • Are the services real, measurable, and proportionate to the payment?
  • Who ultimately receives the economic benefit?

If compliance cannot answer those questions, due diligence is incomplete.

The Limits of Disclosure and Recusal

Many organizations would respond to these facts by strengthening annual conflict questionnaires. That would help, but it would be insufficient. Annual disclosures capture static information. The Clippers matter involved dynamic relationships developing across sponsorship, procurement, personal investment, consulting, endorsement, and expense activity. No annual form could evaluate the full risk unless the organization also had transaction-level escalation.

Recusal presents a similar challenge. An executive can abstain from the final signature and still shape the outcome through introductions, recommendations, term-sheet comments, internal advocacy, or communications with the vendor. Effective recusal must address influence, not merely signature authority.

A defensible conflict process should contain four elements.

  1. Your organization needs a broad definition of conflict. It should cover actual, potential, and perceived conflicts, including close personal relationships, family roles, outside investments, prior professional affiliations, and benefits directed to third parties at an employee’s request.
  2. Disclosures must be tied to decisions. Procurement, legal, finance, compliance, and business approvers should receive relevant conflict information before approving the transaction.
  3. Independent reviewers or monitors must have access to the entire relationship. A sponsor agreement, consulting contract, personal investment, and endorsement deal cannot be reviewed in separate silos when they involve the same parties.
  4. Your organization must document how it managed the conflict. (Document Document Document) Approval should identify the business rationale, benchmarking, competitive process, recusals, alternative providers, deliverables, monitoring plan, and responsible control owner.

An Internal Control Issue, Not Just an Ethics Issue

Conflicts are frequently treated as personal ethics matters. They are also internal control risks. The COSO Internal Control–Integrated Framework provides the right lens. The control environment establishes expectations for integrity and accountability. Risk assessment identifies where influence and commercial pressure could distort decisions. Control activities impose approvals, segregation of duties, and documentation. Information and communication move relevant facts to independent decision-makers. Monitoring determines whether the controls work over time.

When conflicts span several transactions, the control system must aggregate information. A procurement reviewer may see a vendor contract. Finance may see an advance payment. Marketing may see an endorsement agreement. The owner’s office may see an investment. Compliance must be all four.

This is also a governance question. Under the Organizational Sentencing Guidelines, governing authorities must understand the compliance program and reasonably oversee its implementation and effectiveness. Board oversight becomes especially important when a transaction involves senior executives, controlling owners, or stakeholders whose commercial importance may compromise ordinary review.

The Clippers investigation shows that a conflict can exist without a secret ownership interest or a direct personal payment. It can arise when influence, relationships, and commercial leverage align to deliver a benefit that the organization could not provide directly.

Tomorrow in blog post 3, we will examine why the Clippers matter represents an internal controls failure and how procurement data, payment analytics, expense monitoring, and a substance-over-form review could have identified the pattern earlier.

Categories
Blog

2024 ECCP on Accessing Data

In the recently released 2024 Update to the Evaluation of Corporate Compliance Programs (2024 ECCP), the Department of Justice (DOJ) has brought new challenges and opportunities for compliance professionals. One of the most significant changes revolves around data access and the role data plays in an effective compliance program. In this blog post, we’ll explore the key takeaways from the updated guidance and what compliance professionals must do to meet these new expectations, especially when gaining and maintaining access to the right data. This is no longer just about best practices; it is now table stakes. Matt Kelly and I explored this question in this week’s Compliance into the Weeds edition.

Now More Than Ever

One of the most notable aspects of the DOJ’s 2024 update is its focus on data access for compliance professionals. The DOJ has made it clear that if you do not have sufficient access to data, you cannot adequately monitor compliance, detect issues, or remediate problems. Compliance officers are no longer given a pass when they say, “I didn’t have access to the data.”

How did we get here? Part of this shift can be attributed to companies that have demonstrated excellence in leveraging data to bolster their compliance programs. Through the heat of DOJ investigations, these businesses have proven that with the right data, compliance officers can detect misconduct more quickly and prevent violations altogether. At the same time, the DOJ recognizes that many companies still struggle to provide their compliance teams with the data they need to do their jobs effectively.

Data Access: From Best Practice to Table Stakes

In prior years, having a robust data analytics program for compliance was considered a gold standard. It was an aspirational goal that companies could work toward. However, as the DOJ has seen companies implement highly effective data programs, what was once a best practice is now table stakes. If your compliance program can’t access the right data in real-time or near-real-time, you’re not just behind the curve—you’re putting your organization at risk.

Compliance officers can now point to this updated guidance and tell senior management: “This isn’t optional anymore.” You need the resources, tools, and support to access and analyze data effectively. The DOJ’s guidance clarifies that if your company faces an investigation, the inability to access relevant data won’t just be an inconvenience; it will be seen as a compliance failure.

The Six Key Questions: A Roadmap for Data Access

The 2024 ECCP includes six specific questions related to data access, which serve as a roadmap for what compliance officers need to ask within their organizations. While a DOJ prosecutor may not ask all six in any given case, companies should be prepared to answer them all. We will break down how compliance professionals should approach each of these questions.

Does Compliance Have Sufficient Access to Data?

The first question asks whether compliance and control personnel have direct or indirect access to relevant data sources for timely and effective monitoring or testing. In other words, can the compliance team get the information they need when they need it?

This can be a major hurdle for many companies, especially those with complex IT ecosystems. If you’ve gone through multiple mergers and acquisitions, chances are you’re dealing with a variety of legacy systems that don’t “talk” to each other. Compliance officers might find themselves chasing down data from various silos across different business units, which can delay their ability to spot red flags.

What You Should Do

  • Map out your data sources. Know where all relevant data resides, from ERP systems to HR software and procurement platforms.
  • Identify bottlenecks. If your compliance team encounters roadblocks when accessing data, document those challenges and bring them to senior management.
  • Collaborate with IT. Ensure that IT systems are integrated and compliance has the tools to pull and analyze data without delay.

Are There Impediments to Accessing Data?

The second question focuses on barriers preventing compliance from accessing data. These barriers could be structural, such as outdated or incompatible systems, or they could be cultural, such as senior management not prioritizing compliance’s data needs.

What You Should Do

  • Address structural and cultural issues: If your company uses disparate systems, work with IT to create a data lake or central repository for key compliance data. Culturally, ensure that leadership understands the importance of compliance’s access to data and empowers the team accordingly.

Does Compliance Have the Tools to Analyze Data?

Once you can access the data, do you have the tools to analyze it effectively? This question goes beyond simply having access to the data—it’s about whether you have the analytics capabilities to make sense of it.

What You Should Do

  • Invest in the right tools. Data access means nothing if you can’t analyze the information. Invest in data analytics platforms, allowing your compliance team to automate risk assessments, flag potential issues, and generate real-time reports.
  • Train your team. Ensure that compliance personnel are trained on how to use these tools effectively. Analytics without insight is just noise.

Is Data Maintained Properly?

The fourth question concerns data maintenance. Is data stored securely, and is it accurate and reliable? The DOJ wants to ensure that companies don’t just pull data from disparate sources without validating its accuracy.

What You Should Do

  • Validate your data. Work with IT to ensure that data is accurate and up-to-date. Compliance teams need to know that the information they are using is reliable.
  • Establish data governance protocols. Set clear guidelines for data maintenance, including how data should be stored, accessed, and updated.

Is the Company Leveraging Data Analytics to Improve Compliance?

This question is at the heart of the DOJ’s updated guidance. It asks whether companies are using data analytics to create efficiencies in compliance operations and to measure the effectiveness of their compliance programs.

What You Should Do

  • Integrate data analytics into your compliance program. Use data to identify risk patterns, monitor employee behavior, and assess the effectiveness of your compliance efforts.
  • Review your analytics strategy regularly to ensure that you’re continually improving how you use data analytics to enhance your compliance program.
  1. How Precise is Your Data?

Finally, the DOJ asks about the precision of your data. This question goes beyond accuracy—it’s about whether you’re getting the right data at the right level of detail.

What You Should Do

  • Refine your data collection efforts. Ensure you collect precise, relevant data that aligns with your compliance needs. Broad, imprecise data won’t help you detect or prevent misconduct.

Communicating the Importance of Data Access to Senior Management

One of the most important takeaways from the 2024 ECCP update is that compliance officers now have a concrete basis to advocate for better data access. This is no longer about wish lists or best practices—it’s a regulatory expectation. Compliance officers must have honest conversations with senior management and the board about the company’s current data capabilities and where improvements are needed.

Companies often invest in technology when a problem arises, only to pull back once the issue is resolved. This cycle leaves compliance teams under-resourced and needing help to keep pace with evolving risks. The 2024 ECCP gives compliance officers the leverage to push for sustained investments in data access and analytics.

The DOJ’s 2024 update to the Evaluation of Corporate Compliance Programs underscores the critical importance of data access and analytics for modern compliance programs. It is no longer enough to have policies in place; compliance officers need the right data at the right time and the tools to analyze it effectively. The questions posed by the DOJ should serve as a guide for structuring your data access strategy and ensuring that your compliance program is up to the task.

By taking proactive steps to improve data access and analytics, compliance professionals can meet regulatory expectations and build stronger, more resilient programs that can detect and prevent misconduct before it escalates into a serious issue.